Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.
About Cortex XSOAR Discussions
Cortex XSOAR enables SOC analysts to manage alerts across all sources, standardize processes with playbooks, take action on threat intel, and automate response for any security use case.

Discussions

Reopen selected incidents in "Investigation" tab

Hello,

I'd like to reopen the incidents selected after a query in Search Incidents. Not the result of the query, only the selected ones after the query, I'm trying to use the API commando to open them:

 

body = {"id":f"{incident}","version":version}
u

...

Josep_0-1680255394333.png
Josep by L4 Transporter
  • 1285 Views
  • 1 replies
  • 0 Likes

XSOAR customer support problems

I have noticed that many of my recent support cases are being lodged into the XSOAR Queue rather than being assigned a support case owner. Is anyone else having this problem and can anyone advise how I get an update for these cases. I have tried call

...

Resolved! Not getting result of splunk query in xsoar

I am trying one splunk query to fetch some result in xsoar using automation splunk-search, but I am not getting any result in xsoar whereas for the same query I am getting result in splunk, can anyone please help, below is the query:

index=cbuae_wind

...

Himangi by L2 Linker
  • 1157 Views
  • 1 replies
  • 0 Likes

Passing a JSON Value to a JSON API Request

Hi All, I have faced one issue while sending a API call to IVANTI. I need to call one value into this request as below

{
"OrgUnitLink": "${org}",
"Symptom": "${body}",
"Subject": "${incident.labels.Email/subject}",
"Source": "Email",
"Status": "Submitted"
...

Json.PNG
Ivanti.PNG

Custom Web server on XSOAR

Hi,

 

I'ld like to run a simple web server on demand, which would listen for POST requests and put the data posted in a file (or context).

So far I achieved similar by modifying community integration XSOAR-Web-Server, which use long lasting instance

...

Antanas by L2 Linker
  • 970 Views
  • 3 replies
  • 0 Likes

XSOAR Lead Wanted

We are looking for a Cortex XSOAR lead to join our growing team!  What better place to look for the right talent than in the Live Community!!  DM for more information if you have the skillset, are motivated to succeed, and want to join a winning orga

...

Resolved! Yara Rules error

Hi,

 

Trying to use yarascan automation from yara pack on marketplace, always receiving "HasMatch: false"

 

Here it goes the printscreen with the command and the contextdata showing the entryid

 

 

The content has that rule

 

 

Could you help?

 

Re

...

FabioFerreira_0-1679411632399.png
FabioFerreira_1-1679411743582.png

SetGridField

How can I map keys (query, network.cidr, network.country) to a table? I'm trying with below command, is not working for CIDR & Country.

!SetGridField context_path="Whois.IP" grid_id="whoisipinfo" overwrite="true" columns="IP Address,CIDR,Country" key

...

How to realign taskIds number

Hello,

While I'm creating a playbook, the taskids don't follow the proper order due to the changes made.

How can these tasks be realigned to follow an ascending order?

Thanks,

Josep

Josep by L4 Transporter
  • 606 Views
  • 1 replies
  • 0 Likes
  • 943 Posts
  • 30 Subscriptions
Top Solution Authors
Top Liked Authors